CreateRole
CreateRole
Event
Creates a project or organization custom role with selected supported permissions. Creating the definition does not bind it to a principal.
Security Context
A sensitive role can prepare a later privilege grant, but its name does not establish intent. No account permission change is shown until a binding or other effective access path is established; the standalone account-manipulation mapping has been removed.
Log Source
Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.CreateRole. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Check role scope, included permissions, launch stage, creator authority, and approved purpose.
- Find actual bindings and recipients, including later SetIamPolicy events; distinguish role creation from granting it.
- Assess effective access and subsequent use rather than assuming a later grant or reduced detection.
Sample Event
Synthetic scenario. The sample defines pipeline_break_glass with several sensitive permissions. It shows no binding or later use.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.roles.create invocation-id/90000000000000000000001111101111 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T15:32:08.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "iam.googleapis.com", "methodName": "google.iam.admin.v1.CreateRole", "authorizationInfo": [ { "resource": "projects/fantasticlogs-prod", "permission": "iam.roles.create", "granted": true, "resourceAttributes": { "service": "iam.googleapis.com", "name": "projects/fantasticlogs-prod", "type": "iam.googleapis.com/Project" } } ], "resourceName": "projects/fantasticlogs-prod/roles/pipeline_break_glass", "request": { "@type": "type.googleapis.com/google.iam.admin.v1.CreateRoleRequest", "parent": "projects/fantasticlogs-prod", "roleId": "pipeline_break_glass", "role": { "title": "Pipeline break-glass", "description": "Emergency access for OCCAMY pipeline maintenance", "includedPermissions": [ "iam.roles.update", "iam.serviceAccounts.actAs", "iam.serviceAccountKeys.create", "logging.logs.delete", "logging.exclusions.create", "compute.instances.setMetadata" ], "stage": "GA" } }, "response": { "@type": "type.googleapis.com/google.iam.admin.v1.Role", "name": "projects/fantasticlogs-prod/roles/pipeline_break_glass", "title": "Pipeline break-glass", "description": "Emergency access for OCCAMY pipeline maintenance", "includedPermissions": [ "iam.roles.update", "iam.serviceAccounts.actAs", "iam.serviceAccountKeys.create", "logging.logs.delete", "logging.exclusions.create", "compute.instances.setMetadata" ], "stage": "GA", "etag": "QndTQU1QTEVldGFnMTExMT0=" } }, "insertId": "evt001111101111", "resource": { "type": "audited_resource", "labels": { "project_id": "fantasticlogs-prod", "service": "iam.googleapis.com", "method": "google.iam.admin.v1.CreateRole" } }, "timestamp": "2026-04-15T15:32:08.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T15:32:08.821987Z"}